Re: [Full-disclosure] Two biggest Indian University Websites are vulnerable

2010-07-21 Thread Sandeep Sengupta
This is in reply to all those emails which were sent to me privately. I felt another full-disclosure is needed to make few things clear. I do not have time to write back to each one of the critics. --- My conversation with SMU (you will enjoy it) --- 1. Searched google found

[Full-disclosure] Two biggest Indian University Websites are vulnerable

2010-07-17 Thread Sandeep Sengupta
Topic: a) Sikkim Manipal University portal is vulnerable to SQL Injection attack. b) Calcutta University website is spreading malware via iframe code insertion. Details: a) About the university: Sikkim Manipal is one of the largest private University in India. The Institute attracts students

Re: [Full-disclosure] Two biggest Indian University Websites are vulnerable

2010-07-17 Thread Sandeep Sengupta
1. we spoke to Univ system admin over the phone yesterday. They are aware of the problem. Now upto them how much time they will take to rectify it. We hope they atleast have the wisdom to bring the site down till it is debugged. They have the wisest men working for them, after all. 2. In reply to

Re: [Full-disclosure] Two biggest Indian University Websites are vulnerable

2010-07-17 Thread Benji
But you clearly point out that Google had detected it aswell, thus warning the users already (and it took 2 people on your part to discover and screenshot this) On Sat, Jul 17, 2010 at 1:03 PM, Sandeep Sengupta sandeep.sengu...@gmail.com wrote: 1. we spoke to Univ system admin over the phone

Re: [Full-disclosure] Two biggest Indian University Websites are vulnerable

2010-07-17 Thread Valdis . Kletnieks
On Sat, 17 Jul 2010 17:33:44 +0530, Sandeep Sengupta said: 1. we spoke to Univ system admin over the phone yesterday. They are aware of the problem. Now upto them how much time they will take to rectify it. We hope they atleast have the wisdom to bring the site down till it is debugged. That